First published: Tue Oct 25 2022(Updated: )
Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote attackers to read or write arbitrary files via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | <7.1-42661 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27623 is a vulnerability that allows remote attackers to read or write arbitrary files in the iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661.
CVE-2022-27623 has a severity rating of critical with a score of 9.1.
CVE-2022-27623 allows remote attackers to read or write arbitrary files in the iSCSI management functionality of Synology DiskStation Manager (DSM) before version 7.1-42661.
Remote attackers can exploit CVE-2022-27623 by sending unspecified vectors to the iSCSI management functionality of Synology DiskStation Manager (DSM) before version 7.1-42661.
Yes, a fix is available for CVE-2022-27623. Users should update their Synology DiskStation Manager (DSM) to version 7.1-42661 or later.